2.5

CVE-2026-20757

Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server.



This issue affects Command Centre Server: 

9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GallagherCommand Centre Version < 9.10.4647
GallagherCommand Centre Version >= 9.20.1043 < 9.20.3783
GallagherCommand Centre Version >= 9.30.1594 < 9.30.3382
GallagherCommand Centre Version >= 9.40.1359 < 9.40.1976
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosures@gallagher.com 2.5 1 1.4
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-667 Improper Locking

The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-20757
Vendor Advisory